Hi there!
I'm using MODx 2.2.15 in a project, where I created an editor-user who has restricted access in the mgr-context.
The Editor-user has to be able to access the Security - Manage Users-area to activate/deactivate users that have registerred to the site. This is working fine for me atm...
But the Editor-user is also able to edit the admin-profile, even to deactivate and delete it.
How can I prevent the admin-profile from being edited by any other user than the admin himself?
-
☆ A M B ☆
- 24,524 Posts
Unfortunately MODX doesn't provide any granularity in user management permissions.
You'll need a plugin probably using OnUserFormPrerender (before the user editing form is generated), that checks the current user and the user he's trying to edit.
Hello susan!
And thanks a lot for your answer!
I thought this might be usual, but I'm gonna have a deeper look about the mentioned way by using a plugin.
-
☆ A M B ☆
- 24,524 Posts
It would probably be easier to use groups than actual individual users, if the current user is a member of group Editors then he is denied access to the editing form for members of group Administrator. Or if the current user is NOT a member of group Administrator then he cannot edit a member of group Administrator. Something like that.